Skip to main content
Patient and clinical data is among the most sensitive information a clinic handles. Sigma Health HMIS is built with security as a foundation — not an afterthought. Every layer of the platform, from how data is stored to how staff access it, is designed to keep your records safe, private, and entirely under your control.

Data Ownership

Your clinic owns 100% of the health records and operational data you create in Sigma Health HMIS. Sigma claims no ownership over customer data and never sells, licenses, or monetises it in any form. You are the data controller; Sigma acts only as a processor on your behalf, following your instructions to store, organise, and retrieve your information.

Encryption

All data in Sigma HMIS is encrypted at every stage — whether it is sitting in storage or moving between your device and our servers.
At rest — AES-256 encryption: Every record stored in Sigma HMIS, including invoices, claim documents, payment reconciliation data, and patient identifiers, is encrypted using AES-256, the same standard used by financial institutions and government agencies worldwide.
In transit — TLS 1.3: All data transmitted between your browser or mobile device and Sigma’s servers is protected by TLS 1.3, the most current and secure version of the Transport Layer Security protocol. Connections that do not meet this standard are rejected automatically.

Tenant Isolation

Sigma HMIS is a multi-tenant platform, but your data is never commingled with another organisation’s. Each clinic operates inside a strictly isolated environment with dedicated logical boundaries. Access controls ensure that no other organisation — including other Sigma customers — can read or modify your data. Your environment behaves as if it were exclusively yours.

Access Control

Sigma enforces role-based access control (RBAC) on every request made to the platform. When a staff member attempts to view a billing record, submit a claim, or reconcile a payment, the system checks their assigned role before granting access. Staff can only see and act on the data their role explicitly permits. Every access event is logged and audited. This means your administrators have a complete trail of who accessed what and when — essential for compliance reviews and incident investigations.
Assign staff the minimum role necessary for their job function. Limiting access reduces your exposure if a credential is ever compromised.

Data Retention

Sigma retains your data for the duration of your active subscription. Here is what happens at each stage:

Active Subscription

All data is retained in full and accessible to your team at any time. No data is purged while your account remains active.

After Cancellation

You have a 30-day export window from your cancellation date to download your full dataset. After this window closes, Sigma initiates permanent, irreversible deletion of your data.

Backup Rotation

Encrypted backup archives are maintained on a 90-day rolling rotation. Older backups are overwritten automatically, ensuring historical snapshots do not persist beyond this window.
Do not wait until the last day of your cancellation period to export your data. Initiate your export as soon as you decide to close your account to ensure you have adequate time to verify completeness.

Sub-processors

Sigma works with a limited set of third-party sub-processors to deliver the platform. These include cloud hosting and storage providers, transactional email services, and monitoring tools. Every sub-processor is bound by a Data Processing Agreement (DPA) that mandates security standards equivalent to or stricter than those Sigma applies to its own systems. Sigma does not engage sub-processors that are not contractually obligated to protect your data. You may request a current list of sub-processors by contacting privacy@sigmaconnect.org.

International Data Transfers

If your clinic operates in a region where data may be processed or replicated across international borders, Sigma uses Standard Contractual Clauses (SCCs) — the legally recognised mechanism for lawful international data transfers — along with region-specific compliance protocols where required by local regulation. Your data is never transferred internationally without appropriate legal safeguards in place.

Your Rights

As a Sigma HMIS account holder, your clinic administrator has the following rights over your data:
  • Data export: Request a complete export of all your clinic’s data at any time during your active subscription.
  • Correction: Request the correction of any inaccurate account-level or operational records held by Sigma.
For inquiries about individual patient data rights (such as access, rectification, or erasure under applicable health privacy laws), direct those requests to the treating institution. Sigma processes patient data strictly on behalf of its clinic customers and cannot act on individual patient requests directly. To exercise any data rights, contact Sigma’s Data Protection team: Email: privacy@sigmaconnect.org
Sigma Health HMIS is an operational platform for licensed healthcare organisations. Pediatric data governance — including parental consent, minor record access, and age-appropriate data handling — is the responsibility of the treating institution under the applicable laws of its operating jurisdiction.